Conversation

oh guh I still need to fix the certs for some of my stuff

1
0
0

@skydotbit i wish ssl certificates were permanent, or at the very least didnt depend on the date/time
i honestly dont get why having a certificate for a domain name you used to own when someone else buys it later on is much of a security issue

1
0
0

@kemona_halftau @skydotbit because then anyone who has previously owned a domain (or had control of it at any point) can impersonate anyone else who has it in the future. with the current system where any cert signed by a CA for the right hostname is automatically trusted (and not everything checks revocation (for example neither curl nor wget complains about https://revoked.badssl.com/)), that would be a terrible idea.

0
0
0